mukul975
- 828 skills
- 0 followers
- 25k repo stars
- 2 weeks ago last updated
- ▌ Exploiting Adcs With Certipy · mukul975 bundleEnumerate and exploit Active Directory Certificate Services ESC1 through ESC16 misconfigurations with Certipy, including SAN abuse, NTLM relay to web enrollment (ESC8), and golden certificate forgery.
- ▌ Hunting Saas Sso Token Abuse · mukul975 bundleDetect SSO and OAuth token replay and SaaS lateral movement using identity telemetry from Microsoft Entra ID and Okta.
- ▌ Implementing Cloud Waf Rules · mukul975 bundleDeploy and tune Web Application Firewall rules on AWS WAF, Azure WAF, and Cloudflare to protect cloud-hosted applications against OWASP Top 10 attacks, including managed rule sets, custom rate limiting, bot management, and false positive reduction.
- ▌ Securing AWS Iam Permissions · mukul975 bundleHardens AWS IAM configurations to enforce least privilege access across cloud accounts, covering policy scoping, permission boundaries, Access Analyzer integration, and credential rotation.
- ▌ Securing Kubernetes On Cloud · mukul975 bundleHardens managed Kubernetes clusters on EKS, AKS, and GKE by implementing Pod Security Standards, network policies, workload identity, RBAC scoping, image admission controls, and runtime security monitoring.
- ▌ Hunting For Webshell Activity · mukul975 bundleHunt for web shell deployments on internet-facing servers by analyzing file creation in web directories, suspicious process spawning from web servers, and anomalous HTTP patterns.
- ▌ Implementing AWS Security Hub · mukul975 bundleDeploy AWS Security Hub as a centralized cloud security posture management platform, aggregate findings from GuardDuty, Inspector, Macie, and third-party tools, enable security standards, configure automated remediation, and build compliance dashboards across multi-account AWS organizations.
- ▌ Modeling Threats With Opencti · mukul975 bundleModel threat actors, intrusion sets, campaigns, and TTPs as a STIX 2.1 knowledge graph in OpenCTI using the pycti Python client, connectors, and import workers for structured cyber threat intelligence.
- ▌ Moving Laterally With Netexec · mukul975 bundleEnumerate SMB, WinRM, LDAP, and MSSQL services, validate credentials, spray passwords, and execute commands on remote hosts using NetExec during authorized penetration tests.
- ▌ Profiling Threat Actor Groups · mukul975 bundleDevelops comprehensive threat actor profiles for APT groups, criminal organizations, and hacktivist collectives by aggregating TTP documentation, historical campaign data, tooling fingerprints, and attribution indicators from multiple intelligence sources.
- ▌ Securing Serverless Functions · mukul975 bundleHardens serverless compute platforms (AWS Lambda, Azure Functions, Google Cloud Functions) by enforcing least privilege IAM roles, eliminating hardcoded secrets, scanning dependencies for vulnerabilities, validating input, securing function URLs, and enabling runtime monitoring.
- ▌ Testing Cors Misconfiguration · mukul975 bundleIdentify and exploit Cross-Origin Resource Sharing misconfigurations that allow unauthorized cross-domain data access and credential theft during authorized security assessments.
- ▌ Building Soc Escalation Matrix · mukul975 bundleBuild a structured SOC escalation matrix defining severity tiers, response SLAs, escalation paths, and notification procedures for security incidents.
- ▌ Defending Llms With Guardrails · mukul975 bundleDeploy Llama Guard, NeMo Guardrails, and LLM Guard as runtime input/output scanners to block jailbreaks, prompt injection, and toxic content in production LLM applications.
- ▌ Detecting Dependency Confusion · mukul975 bundleDetect and prevent public-over-private name resolution in npm, PyPI, and Maven dependency manifests.
- ▌ Detecting Shadow API Endpoints · mukul975 bundleDiscover and inventory undocumented API endpoints by comparing live traffic against OpenAPI specs, scanning code repositories, and analyzing cloud configurations.
- ▌ Generating And Analyzing Sboms · mukul975 bundleGenerate CycloneDX and SPDX SBOMs from container images and filesystems, scan them for vulnerabilities with Grype, and sign attestations with Cosign for supply-chain trust.
- ▌ Hunting For Ntlm Relay Attacks · mukul975 bundleDetect NTLM relay attacks by analyzing Windows Event 4624 logon type 3 with NTLMSSP authentication, identifying IP-to-hostname mismatches, Responder traffic signatures, SMB signing status, and suspicious authentication patterns across the domain.
- ▌ Performing Ransomware Response · mukul975 bundleExecutes a structured ransomware incident response from initial detection through containment, forensic analysis, decryption assessment, recovery, and post-incident hardening.
- ▌ Performing Vlan Hopping Attack · mukul975 bundleSimulates VLAN hopping attacks using switch spoofing and double tagging techniques in authorized environments to test VLAN segmentation effectiveness and validate switch port security configurations against Layer 2 bypass attacks.
- ▌ Testing Websocket API Security · mukul975 bundleTests WebSocket API implementations for security vulnerabilities including missing authentication, Cross-Site WebSocket Hijacking, injection attacks, and denial-of-service.
- ▌ Analyzing Kubernetes Audit Logs · mukul975 bundleParses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access. Builds threat detection rules from audit event patterns.
- ▌ Analyzing Linux Kernel Rootkits · mukul975 bundleDetect kernel-level rootkits in Linux memory dumps using Volatility3 plugins and live system scanners to identify hooked syscalls, hidden modules, and tampered structures.
- ▌ Conducting API Security Testing · mukul975 bundleConducts security testing of REST, GraphQL, and gRPC APIs to identify vulnerabilities in authentication, authorization, rate limiting, input validation, and business logic using the OWASP API Security Top 10 framework.
- ▌ Configuring Hsm For Key Storage · mukul975 bundleConfigure Hardware Security Modules (HSMs) using the PKCS#11 standard interface for key generation, signing, encryption, and key management with both physical HSMs and SoftHSM2 for development.
- ▌ Detecting Golden Ticket Forgery · mukul975 bundleDetect Kerberos Golden Ticket forgery by analyzing Windows Event ID 4769 for RC4 encryption downgrades, abnormal ticket lifetimes, and krbtgt account anomalies in Splunk and Elastic SIEM.
- ▌ Operating Havoc C2 · mukul975 bundleBuild and operate a Havoc C2 framework for authorized red-team engagements, including team server deployment, evasive Demon agent generation, and post-exploitation.
- ▌ Operating Sliver C2 · mukul975 bundleStand up a Sliver C2 server and listeners, generate cross-platform implants and beacons, and run post-exploitation, pivoting, and BOF/.NET tooling via the armory for adversary emulation.